CVE-2026-59094
HIGHPathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matching in Document Store
Title source: cnaDescription
Pathway through 0.31.1, fixed in commit d09722e, document store applies a caller-supplied glob pattern to indexed document paths using a hand-written recursive matcher that branches two ways on each ** token without memoization, giving exponential worst-case complexity. The filepath_globpattern value is taken from the body of the unauthenticated HTTP endpoints /v1/retrieve, /v1/inputs and /v2/answer and compiled into a filter evaluated once per indexed document, with no length or **-count limit. A remote unauthenticated attacker can submit a short pattern containing many ** tokens to consume CPU for tens of seconds per request, and a small number of requests denies service.
References (4)
Core 4
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/pathwaycom/pathway/issues/241
Patch patch
Fix Commit
https://github.com/pathwaycom/pathway/commit/d09722eef03fd94bba701836eb4c7fbfa3d3b88e
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/pathway-unauthenticated-denial-of-service-via-exponential-glob-pattern-matching-in-document-store
Scores
CVSS v3
7.5
EPSS
0.0047
EPSS Percentile
38.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-407
Status
published
Products (2)
pathwaycom/pathway
< 0.31.1
pathwaycom/pathway
d09722eef03fd94bba701836eb4c7fbfa3d3b88e
Published
Jul 02, 2026
Tracked Since
Jul 03, 2026